Security
How to tell if a photo is AI-generated
A donation appeal with a heartbreaking photo. A "friend" in trouble abroad, with a picture to prove it. A product review with a "customer" photo that never existed. The advice you've probably heard — count the fingers, look for garbled text — worked for a while and is quietly going out of date. Here's what actually still catches a fake, and what to do when nothing does.
Why "look closely" stopped being the whole answer
Early AI image tools left obvious fingerprints: extra fingers, melted text, jewelry that didn't match itself from one earlob to the other. Newer models fix most of that. Security researchers now say plainly that you can't reliably spot an AI image by eye anymore — the fixed list of "tells" people learned in 2023 and 2024 is becoming outdated as the models improve. A few of the old signs are still worth a glance (inconsistent lighting, distorted reflections, jewelry or patterns that don't repeat correctly), but treating them as proof either way is no longer safe. This is the same shift covered in how to tell if a phone call is an AI voice clone: the fake got good enough that "it looks/sounds right" stopped being evidence of anything.
What actually still works: check for a credential, not a clue
Instead of squinting at the image, check what the file itself says about where it came from.
- Content Credentials (C2PA). This is an industry-backed standard — Adobe, Google, Microsoft, and Sony all support it — that attaches a verifiable record of how an image was made or edited. Upload the image at the free Content Credentials Verify tool (contentcredentials.org) and it will show you the manifest: a real camera photo shows capture data like the device and exposure settings; a generated image shows the tool that made it and the generation date.
- SynthID. Google's invisible watermark is embedded directly in the pixels of images made with supported tools, so — unlike a visible logo — it survives cropping and normal edits. You can check for it for free through the Gemini app, or Google's dedicated SynthID detector.
- OpenAI's verify tool. OpenAI runs a free checker (openai.com's verify tool) that reads both C2PA credentials and SynthID watermarks from an uploaded image in one place.
The honest caveat, worth taking seriously: a missing credential doesn't prove a photo is fake. Plenty of real photos never had one attached, and plenty of older or unsupported AI tools don't add one either. A found credential is strong evidence; an absent one just means you learned nothing and need to check another way.
The other free check: does this photo exist anywhere else?
Reverse image search doesn't tell you "AI or not" directly, but it answers a more useful question: has this exact photo shown up somewhere it shouldn't have? Drop the image into Google Lens, TinEye, or Bing Visual Search. A "customer testimonial" photo that turns out to be a stock model from three other websites, or a "family member stranded abroad" photo that's actually a decade-old unrelated news image, tells you what you need to know without any AI-detection tooling at all. Same caveat as above in reverse: no matches doesn't mean the photo is genuine — a brand-new personal photo often won't appear anywhere else yet either.
Where this actually matters
You don't need to run a forensic check on every photo you scroll past. It's worth the two minutes specifically when a photo is being used to move you toward an action — especially money, personal information, or urgency:
- Donation appeals using a dramatic photo, particularly ones pushing for a fast decision or an unusual payment method (gift cards, crypto, wire transfer — the same red flags as AI-written scam emails).
- "Proof" photos in a scam-adjacent conversation — a stranded relative, an online romantic interest who can never video call, a seller with no other listings.
- Reviews or testimonials you're using to decide whether to buy something or trust a business.
- Anything a stranger sent you that's driving an urgent decision. The urgency is usually the actual attack, same as with a cloned voice — the photo is just this year's version of the pressure tactic.
Keep this ready: the 90-second check
1. Is this photo asking me to do something — send money, share
info, trust a stranger, act fast? If not, skip the check.
2. Run it through a reverse image search (Google Lens or TinEye).
Does it appear anywhere else, under a different story?
3. If it matters enough, check for a Content Credential at
contentcredentials.org or Google's SynthID checker.
4. No result either way isn't proof of anything. Fall back to
the same rule as a suspicious call: verify through a channel
the sender doesn't control before you act.
Keep your head:
Looking harder at the picture isn't the safeguard it used to be. Checking where the picture came from — a credential, a reverse search, an independent channel — still is. Save the scrutiny for the photos that are asking you to do something.
Get one of these a week. Our free newsletter sends one genuinely useful AI habit and one judgment check every week — no hype, four-minute read. Subscribe on the home page.
Related: How to tell if a phone call is an AI voice clone and How to spot an AI-written scam email.